Security Engineer - SAST/DAST in Bengaluru, India is listed on Jobeax. Browse 30,000+ vacancies available.
Role : Security EngineerInfrastructure & Security - Bengaluru - Full-Time - On-SiteAbout OTPless : OTPless is India's authentication company - and we're on a mission to make OTPs https://jobeax.com/link/TRG7bY728uRyHLrY help enterprises deliver the fastest, most seamless login experience while improving both conversion and security. Built for high-scale internet companies, OTPless transforms login from a friction point into a measurable growth lever. India's top unicorns trust us. We authenticate 200M+ mobile identities every month - at population https://jobeax.com/link/Qppr0WvBdKijniX6've raised $8M from tier-1 global investors including General Catalyst, SIDBI, and FJ Labs. We're 10 people with the ambition of 1,000.Team & Culture : Our founders are former unicorn builders - people who know what scale, velocity, and disciplined execution actually look like. We operate with the urgency of a startup and the standards of a high-performance https://jobeax.com/link/HbjByC11eva7wNZ8 reward merit, action, ownership, integrity, and ethics. Impact beats titles. Accountability beats https://jobeax.com/link/WRiYgSVpaAVX0F4R you want disproportionate responsibility, direct founder access, and the chance to shape a product category from the ground up - you'll love it https://jobeax.com/link/ASqzekG1uKfCw5VF Role : We're hiring a Security Engineer whose primary mandate is to raise and continuously improve the security posture of OTPless - across our product, infrastructure, and https://jobeax.com/link/0kv4a3i7lkU71yZM is the most security-sensitive layer of any product stack. Our clients - India's top unicorns and fast-scaling enterprises - trust OTPless to protect 200M+ identities every month. That trust is earned through rigorous, proactive security. This role owns https://jobeax.com/link/7IP5gkTw8medOkwY'll lead vulnerability assessments, harden production systems, drive compliance across SOC 2, ISO 27001, GDPR, and PCI-DSS, own endpoint security, and build a security-first culture through training and awareness. You'll also be our frontline defence against the rapidly growing class of AI-powered threats - prompt injection, automated credential attacks, AI-generated phishing, and adversarial model https://jobeax.com/link/EDnxpQ5UNqmziICI is a high-trust, high-ownership IC role. You'll work closely with Engineering, Infrastructure, and Leadership - and your work will directly determine how much enterprise clients trust us with their most critical user https://jobeax.com/link/Sf93bPglbwz3NgBz isn't a checklist here. It's a competitive advantage - and you'll be the one building https://jobeax.com/link/yI74YIvB8C0whsyf You'll Do : - Own the end-to-end security posture of OTPless - identify gaps, prioritise risks, and drive remediation across teams.- Conduct regular vulnerability assessments and penetration tests across production systems, APIs, mobile SDKs, and cloud infrastructure.- Perform static and dynamic application security testing (SAST/DAST) and track findings to closure.- Manage a responsible disclosure / bug bounty programme and triage external security reports.- Monitor CVEs, threat intelligence feeds, and security advisories relevant to our stack and act proactively.- Harden cloud infrastructure (AWS/GCP/Azure) - IAM policies, network segmentation, secrets management, and least-privilege enforcement.- Implement and maintain security controls across CI/CD pipelines - dependency scanning, container security, and secure build practices.- Oversee endpoint security across all company devices - MDM, EDR tooling, patch management, and access controls.- Conduct threat modelling for new product features and infrastructure changes before they ship.- Define and enforce secure coding standards; embed security reviews into the engineering workflow.- Identify and mitigate emerging AI-powered attack vectors - automated credential stuffing, AI-generated phishing, adversarial prompt injection, and synthetic identity fraud.- Assess risks introduced by internal AI tool usage (LLM integrations, copilot tools, AI-assisted workflows) and establish guardrails.- Stay current on the evolving AI threat landscape and translate research into practical defensive controls.- Drive and maintain compliance with SOC 2, ISO 27001, GDPR, and PCI-DSS - including evidence collection, gap remediation, and audit readiness.- Liaise with external auditors, certification bodies, and enterprise clients during security assessments.- Maintain security policies, procedures, and documentation to audit-ready standards at all times.- Track regulatory changes across applicable frameworks and update internal controls accordingly.- Design and run security awareness training for all employees - phishing simulations, secure coding workshops, and onboarding modules.- Champion a security-first engineering culture - make secure-by-default the path of least resistance for every team.- Build incident response playbooks and lead tabletop exercises to keep the team prepared.- Act as the internal point of contact for security questions, escalations, and policy https://jobeax.com/link/p1OBTLQZ6uwV3haN We're Looking For : Must-Have : - 4 - 5 years of hands-on experience in application security, infrastructure security, or a broad security engineering role.- Proven experience conducting vulnerability assessments and penetration tests across web applications, APIs, and cloud environments.- Strong working knowledge of cloud security on AWS, GCP, or Azure - IAM, VPCs, secrets management, and security monitoring.- Hands-on experience with SAST/DAST tools, dependency scanning, and secure CI/CD practices.- Deep familiarity with compliance frameworks : SOC 2, ISO 27001, GDPR, and PCI-DSS - including audit preparation and evidence management.- Solid understanding of endpoint security - MDM, EDR tools, patch management, and device policy enforcement.- Awareness of AI-powered attack vectors and how to defend against them in a production authentication environment.- Strong written communication - able to write clear policies, audit evidence, and risk reports for both technical and non-technical audiences.- Ownership mindset - you don't wait for security incidents; you prevent https://jobeax.com/link/nyu7eizxzKW4FnkL to Have : - Industry certifications : OSCP, CEH, CISSP, CISM, AWS Security Specialty, or equivalent.- Experience with authentication protocols and identity security - OAuth 2.0, OpenID Connect, OTP systems, or similar.- Familiarity with mobile security (Android/iOS) - relevant given OTPless's SDK footprint.- Experience running a bug bounty or responsible disclosure programme.- Prior work at a fintech, identity, or developer-tools company where security is product-critical.- Experience with SIEM tools, log analysis platforms, or threat detection https://jobeax.com/link/Q6bacvOP0giEITpZ's in It for You : - Own the security function at a company protecting 200M+ mobile identities - with full leadership visibility and trust.- Work on a genuinely security-critical product - authentication is the frontline, and your work directly protects it.- Direct access to founders and engineering leadership; your recommendations will be heard and acted on.- Competitive compensation aligned with your experience.- A fast-evolving threat landscape - especially with AI - that will keep you sharp and learning every week.- High-trust, outcomes-driven culture without micromanagement.- Mentorship from senior engineering leadership including ex-BharatPe https://jobeax.com/link/nhylgT7iBuJDaF4L This Role Matters : OTPless sits at the intersection of authentication, identity, and mobile - three areas that attract sophisticated, well-resourced attackers. Our enterprise clients trust us with the login layer of their products. Any breach, vulnerability, or compliance failure doesn't just affect us - it affects every user across every client we https://jobeax.com/link/5GdgJx7PxMO374Ol the same time, AI is fundamentally changing the threat surface. Attacks are faster, more convincing, and more automated than ever. We need someone who understands this shift - and builds defences that stay ahead of https://jobeax.com/link/HBh5DjV5IwoJL8ZD our first dedicated Security Engineer, you won't be inheriting a mature, documented security programme. You'll be building one - from policy to tooling to culture. That's a rare opportunity for an engineer who wants to own something that genuinely https://jobeax.com/link/wb3TyAxit7TNB2LQ hardening systems, staying ahead of threats, and making security a product advantage sounds like your kind of work - let's talk. (ref:hirist.tech)